Traditional vulnerability management is accelerating toward a reset, with many security organizations considering continuous threat exposure management (CTEM) to better align their operations with the pace of change — and attacks — today. Whereas traditional vulnerability management relies on periodic assessments, with security teams scanning environments, identifying vulnerabilities, and implementing fixes as necessary, CTEM takes a more agile approach, while also broadening beyond vulnerabilities with the aim to continuously understand an organization’s risk exposure across endpoints, networks, identities, cloud environments, applications, and users. “CTEM brings something different to the table in three key areas,” highlights Fernando Maldonado, principal analyst at Foundry Spain. The first, he points out, is scope. In addition to vulnerable software, CTEM also focuses on misconfigurations, identity risks, excessive permissions, and leaked credentials —gateways attackers are increasingly putting to use. “The second is validation, because instead of relying on a score, [CTEM] verifies whether the exposure is truly exploitable and whether current controls would prevent it,” Maldonado adds. The third difference, he says, is mobilization, because the CTEM framework assigns a specific person the responsibility for fixing each issue, which is where things traditionally get bogged down. “The metric shifts from how many vulnerabilities I’ve found to how many real attack vectors I’ve closed,” he concludes. One-off scans are no longer enough The current threat landscape makes it clear that one-off scans are no longer sufficient. Today’s infrastructures are constantly changing. Cloud environments, distributed applications, API integrations, continuous deployments, and automation are constantly changing an organization’s attack surface. “A single snapshot can provide useful information, but it quickly becomes outdated,” says Luis Uribe, offensive security engineer at Factum. “New assets, configuration changes, exposed services, or modifications to permissions can alter the level of risk in a matter of hours or days.” Moreover, attackers are operating increasingly more quickly to exploit very narrow windows of opportunity. “As a result, organizations need a continuous ability to identify, contextualize, and prioritize the vulnerabilities that could actually be used in an attack,” Uribe says. That speed is a key reason why security organizations should consider shifting to CTEM, Foundry Spain’s Maldonado adds. Otherwise, they may be operating blind. “Between assessments, there’s a long period of uncertainty, and attackers, increasingly relying on AI, are taking less time to exploit new vulnerabilities,” he says. “Simply patching and doing nothing is no longer enough.” Volume is another issue, Maldonado says. Tens of thousands of vulnerabilities are published each year, generating unmanageable backlogs where important issues are buried under countless minor findings. And finally, there is coverage to consider, he adds. “Scanners see vulnerable software, but not the identity, the SaaS, misconfigurations, or attack vectors, which is precisely where the attackers gain entry. A scan reveals what is vulnerable, but not what is exploitable or what truly matters to the business. This part of the argument holds true without needing to trust any vendor, because these are structural facts of the environment,” he explains. The role of automation and contextual intelligence Factum’s Uribe notes that automation and contextual intelligence are two essential pillars of the CTEM model. In his opinion, the former allows for continuous visibility into assets, configurations, vulnerabilities, and changes in the environment, facilitating the early detection of new exposures. And while Agustín Serralta, director of services and CISO at SCC España, states that automation is key, it doesn’t replace human judgment. “In complex environments, it’s impossible to manage large volumes of data without automation,” he says. “However, completely delegating decision-making to algorithms can be risky, especially if those models aren’t reviewed or become obsolete.” As a result, contextual intelligence must combine technical context (exploitability, exposure, existing measures) with business context (which systems support critical processes, legal obligations, or contractual commitments), he says. “Without that combination, there is no real risk management, only prioritization based on technical needs,” he says. Javier Castillo, operations director of Secure&IT, says it’s important to note that CTEM doesn’t replace penetration testing or red team activities, which “remain fundamental services for identifying complex vulnerabilities, design errors, logical failures, or advanced attack techniques that can hardly be detected through automated processes,” he says. Therefore, he adds, continuous monitoring and offensive assessments should be understood as com
CTEM can give your security team a contextual edge
Traditional vulnerability management is accelerating toward a reset, with many security organizations considering continuous threat exposure management (CTEM) to better align their operations with the pace of change — and attacks — today. Whereas traditional vulnerability management relies on period
Source: CSO Online